Date : 06 Mar, 2025


What is Nessus?

Nessus is a vulnerability scanner developed by Tenable. It’s widely used by cybersecurity professionals to find weaknesses in systems, applications, and networks.

Faq

Its main job?
To scan systems for known vulnerabilities like missing patches, misconfigurations, weak passwords, and more.

Vulnerability Scanning Using Nessus:


Why use Nessus?

Because it helps:


What can Nessus scan?

Nessus can scan for:


Types of Nessus Scans

Type Description
Basic Network Scan Scans all devices in a network for common vulnerabilities
Advanced Scan Customizable scan with specific plugins, credentials, etc.
Web Application Scanning Detects web vulnerabilities (e.g., XSS, SQLi)
Credentialed Scan Authenticates into the system for deeper scanning
Compliance Scan Checks if systems follow industry standards

How Nessus Works

  1. You configure a target IP or network range in Nessus

  2. Select or customize a scan policy

  3. Start the scan

  4. Nessus runs thousands of plugins to check for known issues

  5. Generates a report with:

    • πŸ”΄ Critical
    • 🟠 High
    • 🟑 Medium
    • πŸ”΅ Low risk vulnerabilities
  6. Nessus provides results in PDF/CSV/HTML formats